8.2 Information Security Risk Assessment
To satisfy ISO/IEC 27001 Clause 8.2, anDREa executes information security risk assessments at planned, regular intervals and whenever significant operational, technical, or organizational changes are proposed or occur. These reviews ensure that our threat landscape mapping remains accurate, current, and aligned with our baseline security criteria.
8.2.1 Risk Assessment Intervals and Triggers
anDREa utilizes two distinct operational mechanisms to evaluate risk and ensure comprehensive coverage:
1. Annual Systemic Assessment (Risk-Control Matrix)
- Execution: The Director maintains and owns the master Compliance and Risk Matrices.
- Interval: This matrix serves as our comprehensive annual risk assessment and undergoes a formal, exhaustive review by the Management Team at least once per fiscal year.
- Dynamic Updates: The matrix is not a static ledger; it is updated continuously throughout the year as new vulnerabilities are identified or when shifts in the macro threat landscape occur.
2. Targeted Appraisals (Security Impact Assessments)
The Management Team conducts granular SIA Register to analyze localized risks triggered by tactical changes. These are mandatory prior to the execution or onboarding of:
- Major platform code changes or features tracked as *Product Backlog Items (PBIs).
- New third-party software tools, suppliers, or corporate infrastructure assets.
- Root-cause analyses following validated security incidents or critical near-miss events.
8.2.2 Documentation and Stakeholder Reporting
To ensure complete auditable evidence of our risk management lifecycle, all assessment inputs and outcomes are preserved systematically:
- Internal Records Preservation: Technical SIAs, assessment drafts, and engineering validation data are logged directly within our secure internal ticket management system and organized within the Decisions, Testing, & Plans folder structure.
- External Stakeholder Reporting: To maintain transparency with institutional clients and compliance partners, finalized, public-facing summaries of these security impact evaluations are compiled, converted to PDF, and distributed transparently to key stakeholders via the monthly CTO Report (see Management Reports).